Security
The practices we use to protect accounts, platform data, and infrastructure.
Infrastructure
Litigation Connection is designed to run on managed cloud infrastructure with encrypted transport, environment-scoped configuration, and database access limited to application and operator workflows.
Authentication
Authentication is handled by Clerk, with support for email/password and OAuth providers. Passwords are not stored by Litigation Connection. Session cookies are configured with modern browser security controls.
Payments
When card billing is enabled, payment processing runs through Stripe. We do not store card numbers.
Data isolation
Tenant-aware application routes resolve user access from the authenticated session and database-backed permissions before returning tenant-scoped data.
How profiles are sourced
Expert and attorney profiles are built from pages the person or their firm published themselves. Every listing names the source domain and the date we read it.
A listing nobody has claimed shows only what the source page stated — name, firm, title, location, practice areas — and never an email address or a phone number. Contact details are relayed by us on request; they are not disclosed to people browsing the directory. Claiming a listing puts the person in control of what it says.
Two opt-outs are open to anyone, with no account: ask us to remove a listing and ask never to be contacted. A do-not-contact request is enforced before any draft, call or export, everywhere on the platform.
Reporting vulnerabilities
Please report suspected vulnerabilities to security@litconnect.com. We review security reports and prioritize confirmed risk quickly.